Configuring Corporate Identity Provider Proxy in SAP Cloud Identity Services
Tutorials that teach this
Docs explaining this concept
Prerequisites
- Concept Configuring SAML Trust Between SAP BTP Subaccount and Identity Provider Configuring SAML trust between an SAP BTP subaccount and an identity provider establishes a federated authentication relationship that allows users to log in to BTP-hosted applications using an external identity provider. A developer uses this configuration to enable single sign-on (SSO) by registering the identity provider as a trusted SAML entity within the subaccount. As described in [Set Up Trust Between SAP Cloud Identity Services and SAP BTP Subaccount](https://developers.sap.com/tutorials/set-up-trust-between-sap-cloud-identity-services-and-sap-btp-subaccount.html), this trust can be established between SAP BTP and SAP Cloud Identity Services, or between SAP BTP and an on-premise system such as SAP S/4HANA.
- Concept SAP Identity Authentication Service (IAS)
- Concept Identity Provider Proxy When SAP Cloud Identity Services acts as an Identity Provider Proxy, it sits between a service provider and one or more upstream corporate identity providers, forwarding authentication requests rather than handling them directly. Developers use this pattern to [establish trust and federation](https://help.sap.com/docs/btp/sap-business-technology-platform/7c6aa87459764b179aeccadccd4f91f3?locale=en-US&state=PRODUCTION&version=Cloud) between SAP Authorization and Trust Management Service and an external identity provider without requiring a direct trust relationship between every service provider and every corporate IdP. This allows a single trust configuration on the SAP BTP side to support multiple upstream identity providers transparently.